Subprocessor Disclosure
This disclosure identifies the external infrastructure currently used by PulseIQ EMS Management. It is effective August 28, 2026. PHI remains prohibited unless all separately stated authorization, agreement, vendor-program, configuration, and certification conditions are completed.
| Provider | Purpose | Expected data | Location | Launch evidence status |
|---|---|---|---|---|
| Supabase, Inc. DPA · Shared responsibility |
Hosted PostgreSQL database, authentication, API, and related platform services. | Agency application, identity, membership, configuration, commercial, audit, support, and customer-entered operational data. | United States; exact project region and transfer terms must be recorded. | Active infrastructure. Account plan, DPA acceptance, backup posture, and PHI/BAA position require retained approval evidence. |
| Netlify, Inc. Privacy · Security |
Static site hosting, TLS delivery, serverless functions, deployment, and operational request handling. | Web requests, limited technical metadata, function inputs and outputs, and environment configuration needed to deliver the service. | Global delivery network / United States provider; exact contractual transfer terms must be recorded. | Active infrastructure. DPA/terms acceptance, security contact, log retention, and plan evidence require verification. |
| Plus Five Five, Inc. (Resend) DPA · Security |
Transactional email delivery for account, invitation, recovery, application, support, and approved platform communications. | Recipient email address, name where supplied, message content, delivery metadata, and provider delivery identifiers. | United States; Resend’s published DPA describes primary processing in the United States. | Active infrastructure. Sending credentials are environment-separated. PHI in email is prohibited; DPA/account evidence and tracking configuration require verification. |
Payment processing
No payment provider is selected or active. PulseIQ’s canonical billing backend is provider-neutral, and provider price identifiers, customer identifiers, webhooks, payment receipts, and reconciliation must be certified in test mode before a payment provider can be added to this list. An approved zero-dollar pilot would still use the contract, subscription, entitlement, provisioning, and activation controls.
PHI and healthcare-data conditions
Supabase’s official documentation states that organizations handling PHI must have a signed BAA, enable its HIPAA add-on, mark and configure HIPAA projects, and meet specified customer responsibilities such as MFA, point-in-time recovery, SSL enforcement, network restrictions, and connection logging. PulseIQ does not represent that these conditions are currently complete. Resend’s standard DPA lists sensitive data as not applicable, so PHI must not be placed in email content or metadata without separate written resolution.
Provider changes
Applicable customer agreements govern notice, objection, emergency replacement, and update procedures for new or changed subprocessors. Proposed additions must complete privacy, security, contract, and data-flow review before receiving customer data.
Contact
Questions about providers or data processing may be sent to support@pulseiqmanagement.com.